remote code execution

PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency patch for its NG and MF print management software to address two critical vulnerabilities. These flaws, CVE-2026-82078 and CVE-2026-81578, were found to be bypassable by initial fixes and allow attackers to achieve authentication bypass and remote code execution. The company urges all customers to install the latest patch, even if they applied the first one, and to implement network access controls as a precautionary measure.

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers are actively exploiting a critical vulnerability in Zimbra Collaboration (ZCS) that allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-73570 with a CVSS score of 8.9, stems from improper input sanitization in the SNMP notification processing. Exploitation can lead to the execution of arbitrary operating system commands as the Zimbra user. Zimbra has released version 10.1.20 to patch this vulnerability, and CERT Polska is urging users to check their logs for signs of compromise.

Hackers Exploiting Unpatched GeoServer Zero-Day
A critical zero-day vulnerability in GeoServer is being actively exploited by hackers. The SQL injection flaw could enable attackers to achieve remote code execution on vulnerable systems.

Cisco Identity Services Engine Vulnerable to Command Injection
A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal
A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
A critical vulnerability has been discovered in the NGINX HTTP WebDAV module that could allow remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied data during WebDAV request parsing, leading to an integer underflow. This could enable an attacker to run code with the privileges of the service account on affected NGINX installations.

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
A critical vulnerability (CVE-2026-42533) has been discovered in NGINX, potentially allowing remote attackers to crash worker processes or even execute arbitrary code. The flaw, present in versions from 0.9.6 up to 1.31.2, arises from a specific configuration involving regex-based maps and string expressions. While F5 has released patches, researchers suggest that existing mitigations might not be entirely effective, emphasizing the need for immediate upgrades.

Two High-Severity WordPress Vulnerabilities Require Immediate Patching
WordPress version 6.9 has been impacted by two significant security flaws. One vulnerability allows for SQL injection, while the other, a REST API issue, could lead to remote code execution. Both have been addressed in the latest security release, version 7.0.2.

Bug in top AI coding agents shows that Unix-era security headaches never really die
A vulnerability dubbed "GhostApproval" has been discovered in at least six popular AI coding assistants, allowing them to access files outside their designated workspaces and potentially execute remote code. The flaw exploits symbolic links, a long-standing security issue, to trick agents into writing malicious content, such as SSH keys, to sensitive system files. While some vendors have patched the issue and assigned CVEs, others have downplayed the risk or are yet to release fixes.